Skip to content

Per-step mode and default action #104

Description

@matthewdevenny

Rollout order after #94 (attribution, PR #95): #103 → #106 → #104 → #105. Builds on the hook #106 lands, so it follows container attribution.

Goal

Let a policy set enforce/audit mode and the default action per workflow step, instead of once for the whole job.

Motivating case: run enforce across a job but audit for one noisy step (a vendored test suite, a flaky integration step) without downgrading the entire job — today --audit-mode is a single boolean fixed for the daemon's lifetime.

Why it's small

Phase 0 already ships the hard part. Mode and default action are single-byte values in eBPF array maps, written through idempotent setters (SetAuditMode, SetDefaultAction) that are already called at runtime when SaaS policy overrides the CLI flag. The work is making the lookup per-policy rather than global:

  • Replace the single-entry map_audit_mode / map_default_action lookups in check_audit_or_block() with a per-policy lookup keyed on the socket's step tag (map_policy_meta[policy_id] → {default_action, audit}).
  • Resolve socket tag → policy id in the TC path (the tag is already embedded in events; this extends it to the verdict path for these two fields only).
  • Policy schema: per-step mode / default_action overrides on top of the job baseline.

Requirements

  • Sockets with no tag (pre-attach, or attribution unavailable) must resolve to the job baseline, never to a looser step policy.
  • If step attribution fails to start, behavior must be identical to today's job-wide mode — the existing warn-and-degrade path.
  • Established sockets keep their birth tag, so a step's mode applies to the connections that step created, including ones that outlive it.

Done when

A workflow can declare a different mode for one step, the audit log/summary show that step's events under the declared mode, and every other step is unaffected.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions